Close Menu
geekfence.comgeekfence.com
    What's Hot

    Wilkie refers gambling concerns to anti-corruption commission

    August 13, 2026

    Lumen ready for AI traffic rush – with programmable fabric and “more fiber than anyone”

    August 13, 2026

    With a feel for physics, AI models simulate a wider range of real-world scenarios | MIT News

    August 13, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Software Engineering»Dwayne McDaniel on the Engineering Challenges of Secrets Management – Software Engineering Radio
    Software Engineering

    Dwayne McDaniel on the Engineering Challenges of Secrets Management – Software Engineering Radio

    AdminBy AdminMay 29, 2026No Comments2 Mins Read13 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Dwayne McDaniel on the Engineering Challenges of Secrets Management – Software Engineering Radio
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Dwayne McDaniel, developer advocate at GitGuardian.com, joins host Priyanka Raghavan to talk about the engineering challenges of secrets management. They explore what “secrets” really are in modern systems—far beyond passwords—including API keys, tokens, certificates, and machine identities, and how “secret sprawl” emerges across the SDLC. Drawing on reports from GitGuardian and Verizon, they discuss the growing scale of secret leaks and why credential abuse and phishing remain dominant attack vectors.

    They examine common leak points—from code repos and logs to CI/CD pipelines, containers, and SaaS integrations—and how cloud, DevOps, and AI tooling are amplifying risks. Priyanka quizzes Dwayne about recent supply chain attacks from pyPi and trivy ecosystems, highlighting recurring root causes like poor access control, long-lived credentials, and weak security hygiene. Finally, they consider detection, response, and modern solutions—short-lived credentials, secret scanning, and identity-based approaches like OWASP NHIR and SPIFFE/SPIRE—ending with practical advice for engineers to reduce blast radius and design for secure secret lifecycle management.

    Brought to you by IEEE Computer Society and IEEE Software magazine.

    Dwayne McDaniel on the Engineering Challenges of Secrets Management – Software Engineering Radio




    Show Notes

    Related Episodes

    1. SE Radio 578: Ori Mankali on Secrets Management using Distributed Fragments Cryptography
    2. SE Radio 311: Armon Dadgar on Secrets Management
    3. SE Radio 680: Luke Hinds on Privacy and Security of AI Coding Assistants
    4. SE Radio 658: Tanya Janca on Secure Coding

    Other References

    1. Dwayne McDaniel
    2. Secrets Security End-To-End – /dev/mtl
    3. YouTube: Dwayne McDaniel – Solving Secrets Sprawl Takes More Than Sec.: Why Machine Id. Is Everyone’s Problem
    4. Real-Life Examples of Non-Human Identity Security Breaches and What to Do About Them (Updated Regularly)
    5. OWASP Non-Human Identities Top 10 – 2025 – OWASP Non-Human Identities Top 10
    6. How GitGuardian Enables Rapid Response to the LiteLLM Supply Chain Attack
    7. The Team PCP Snowball Effect: A Quantitative Analysis



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    SED News: The Kimi Moment, Runaway AI, and Tokenmaxxing

    August 11, 2026

    Jason Gorman on The Effective Use of AI For Software Development – Software Engineering Radio

    August 7, 2026

    The Terminal as an Agentic Interface

    August 6, 2026

    Sonali Varde on AI and the Engineering Manager Role – Software Engineering Radio

    August 2, 2026

    Docker and Sandboxing AI Agents

    August 1, 2026

    Tabs Versus Spaces: Defining a Coding Standard

    July 30, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202576 Views

    The Next Paradigm in Efficient Inference Scaling – The Berkeley Artificial Intelligence Research Blog

    May 16, 202642 Views

    Is it too late to start learning AI and machine learning in my 30s or 40s?

    April 9, 202638 Views
    Don't Miss

    Wilkie refers gambling concerns to anti-corruption commission

    August 13, 2026

    Independent MP Andrew Wilkie has taken the fight over gambling reform to the National Anti-Corruption…

    Lumen ready for AI traffic rush – with programmable fabric and “more fiber than anyone”

    August 13, 2026

    With a feel for physics, AI models simulate a wider range of real-world scenarios | MIT News

    August 13, 2026

    Monitoring beyond SNMP: Turning your network into a sensor

    August 13, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Wilkie refers gambling concerns to anti-corruption commission

    August 13, 2026

    Lumen ready for AI traffic rush – with programmable fabric and “more fiber than anyone”

    August 13, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.